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AMENDMENTS TO THE CLAIMS 

Claims 1-8 are canceled. 

9. (currently amended) A data transfer system comprising: 
a key facility; 

a sender facility configured to communicate with the key facility, the sender facility 
includin p comprisine : 

a first encryption module configured t o encrypt data for an intended recipient, 

wherein to provid e a first encrypted part a nd a remaining encrypted part are produced, the first 
encrypted part carrying information for decryption of the remaining enc rypted part sesuch that 
th* remainin g encrypted part canaet b e decrypted wjfeea^-onlv after decrypting the first 
encrypted part: , a positioning modulo to split the data into onoryptcd porta ouch that no part i s 

d e cryptablo on its own, 

a second encryption module configured t o encrypt at least one of tho porta for a 

tnirH pnrtv the first encrypted part so as t o produce a lurtl^thjrdencrypted pa rt, whieh4sr the 
third encrypted part being decryptable only b v the kev facility,? 

a combiner configured t o combine the farther-third e ncrypted part gnd- awith the 

remaining encrypted part to produce a data block, and 

a first transmitter configured t o send the data block; and 

a receiver facility configured to communicate with the key facility, the receiver facility 
includin gcomprising : 

a receiver configured to receive the data blocks 

a s plitter configured to split the data block in to the third encrypted part and the 
remaining encrypted part; and 

a command module configured to generate a request for the key facility to 
decryptkm-ef the figfee^ -tbird encrypted parr, Wherein the first encrypted part is 
recovered, by tho k o v facilit y, t he receiver further adapted to rec eive the fi rst encrypted 
part from the kev facility : 
wherein the key facility further comprises: 
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a first decryption module configured to decrypt the, third encrypted part-^ggaftgr 
rpr.e-.i pt of the request from the receiver facility, t ho further third encrypted port whereinte 
feveal-the first encrypted part is recovered; and 

a second transmitter configured t o send encrypted part to the receiver 

facility; and 

wherein the receiver facility further comprises a second decryption module configured t o 
decrypt the first_encrypted part *n as to thefebv- ^n a bl e t h e su bsequent decryption of the , 
remaining and tho decrypted further encrypted pa rt p iu vidcd by tho key fa cilit y . 

10. (currently amended) The system of Claim 9, wherein the sender facility includes a 
signature module to sign the data block. 

11. (currently amended) The system of Claim 9, wherein the first transmitter is 
configured to send the data block to the key facility, and wherein the key facility further includes 
a receiver configured to receive Hie data block and to forward the data block to the receiver 
facility. 

12. (currently amended) The system of Claim 11, wherein the key facility further 
includes a log module configured t o log receipt of the data block. 

13. (currently amended) The system of Claim 9, wherein the receiver facility is 
configured to communicate with the key facility and the sender facility, and wherein the first 
transmitter is configured to send the data block to the receiver facility, the receiver facility further 
inoluding comprising a receiver to receive the data block. 

14. (currently amended) The system of Claim 13, wherein the key facility further 
Metedea -comprises a log module configured t o log receipt of the ftati^thh^Lencrypted part. 

1 5. (currently amended) The system of Claim 9, wherein the key facility further includes 
comprises a log module configured t o log receipt of the request for decryption of the fcrt^thjrd 
encrypted part as proof of delivery of the data block to the receiver facility. 
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16. (currently amended) The system of Claim 15, wherein the sender facility further 
H*eto^^^ delivery module configured t o request proof of delivery information from 
the key facility. 

17. (currently amended) The system of Claim 9, wherein the key facility is a trusted third 
party.- * 5 the key facility. 

18. (currently amended) A method of data transfer, comprising: 

at a sender facility: 

encrypting data for an intended wflipien t, wherein to provide-a first encrypted part 
and a remaining encrypted part are produced, the first encrypted p art carrying information 
for decryption of the remaining encrypted pa r t sesuch that the remaining encrypted part 
carmot he decr ypted wifeetttonlv after decrypting t he first encrypted part; 7 

splitting the data into encrypted parts such that no part i s docryptahlo on its own, 

encrypting at loaot one of the porta for a third partj'the first encrypted part to 
produce a farther -third e ncrypted part n the third encrypted part being whieh-i&4ecryptable 
only by the kev facility,? 

combining the fefther -third encrypted part afid^awith the remaining encrypted part 

to produce a data block, and 

sending the data block; 
at a receiver facility: 
receiving the data block^md 

splittin g the data block into the third encrypted p art and the remaining encrypted 
part;? and 

generating a request for the kev facility to d ecrypt the third encrypted 
part rcquonting decryption of the further thircL o ncryptod part by a key facility; 
at the key facility: 

decrypti ng the third encrypted part^-e» after receipt of the request from the 
receiver facility, th e further ttur^oncryptod part,te^eveal-wherein the first encrypted part 
is recovered , and 
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transmitting the decrypt e d furth e ri ng! encrypted part to the receiver facility; 
and 

at the receiver facility: 

receiving the first encrypted part from the key facility: and 
decrypting the first encrypted part so as to thefeW-enable the subsequent 
decryption of the remaining m i d the d e crypted farther encrypted par t provided by the k e y 

'i utility* 

19. (previously presented) The method of Claim 18, further comprising signing the data 
block at the sender facility. 

20. (currently amended) The method of Claim 18, wherein the sending at the sender 
facility iq nnnfigmnH tn nend comprises sending the data block to the key facility, and wherein the 
method further comprises at the key facility receiving the data block and forwarding the data 
block to the receiver facility. 

21. (previously presented) The method of Claim 20, further comprising, at the key 
facility, logging receipt of the data block. 

22. (currently amended) The method of Claim 18, wherein the sending at the sender 
facility i^ configured to send com prises sending the data block to the receiver facility, and 
wherein the method further comprises, at the receiver facility, receiving the data block. 

23. (currently amended) The method of Claim 22, further comprising, at the key facility, 
logging receipt of the fttf&e^third e ncrypted part. 

. 24. (currently amended) The method of Claim 18, further comprising, at the key facility, 
logging receipt of the request for decryption of the fefeef-third encrypted part as proof of 
delivery of the data block to the receiver facility. 

25. (previously presented) The method of Claim 24, further comprising, at the sender 
facility, requesting proof of delivery information from the key facility. 
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26. (currently amended) The method of Claim 18, wherein the key facility is a trusted 

third party, is tho key facility. 

27. (currently amended) A data transfer system comprising: 

a key facility; 

a sender facility configured to communicate with the key facility, the sender 
facility including a first encryption module configured to encrypt data for an intended 
recipient, a partitioning module configured t o split the data into encrypted parts such that 
no part is decryptable on its own, a second encryption module configured to encrypt at 
least one of the parts for the key facility so as t o produce a further encrypted part, a 
combiner configured t o combine the further encrypted part and a remaining encrypted 
part so as t o produce a data block, a signature module configured to sign the data block, 
and a first transmitter configured t o send the data block to the key facility; and 

a receiver facility configured to communicate with the key facility, the receiver 
facility intruding comprising a receiver configured to receive the data block from the key 
facility, and a command module configured t o request decryption of the further encrypted 
part by the key facility; 

wherein the key facility further comprises a receiver configured to receive the data 
block from the sender facility and to forward the data block to the receiver facility, a first 
log module configured t o log recipient of the data block from the sender facility, a 
second log module configured t o log receipt of the decryption request from the receiver 
facility as proof of delivery of the data block to the receiver facility, a first decryption 
module configured t o decrypt the further encrypted part en-after receipt of the request 
from the receiver facility, and a second transmitter configured to send the decrypted 
further encrypted part to the receiver facility; 

wherein the receiver facility further comprises a second decryption module 
configured t o decrypt the encrypted part and the decrypted further encrypted part provided 

by the key facility; and 

wherein the sender facility further includ e s comprises a delivery module 
configured t o request proof of delivery information from the key facility. 
28. (currently amended) A data transfer system comprising: 
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a key facility; 

a sender facility configured to communicate with the key facility and a receiver 
facility, the sender facility «ekid«^onmrising.a first encryption module configured t o 
encrypt data for an intended recipient, a partitioning module configured t o split the data 
into encrypted parts such that no part is decryptable on its own, a second encryption 
module configured t o encrypt at least one of the parts for the key facility soasto produce 
a further encrypted part, a combiner configured t o combine the further encrypted part and 
a remaining encrypted part so as t o produce a data block, a signature module configured 
to sign the data block 4 and a first transmitter configured to send the data block to the 
receiver facility; 

wherein the receiver facility is configured to communicate with the key facility 
and the sender facility, and the receiver farility includes-comprises a receiver configured 
to receive the data block from the sender facility, and a command module configured to 
request decryption of the further encrypted part by the key facility, 

wherein the key facility further comprises a log module configured to log receipt 
of the further encrypted part, a first decryption module configured to decrypt the further 
encrypted part efi-after_receipt of the request from the receiver facility, and a second 
transmitter configured t o send the decrypted further encrypted part to the receiver facility; 
and 

wherein the receiver facility further comprises a second decryption module 
configured t o decrypt the encrypted part and the decrypted further encrypted part provided 
by the key facility. 

29. (currently amended) A method of transferring data, comprising: 
at a sender facility: 

encrypting data for an intended recipient, splitting the data into encrypted 
parts such that no part is decryptable on its own, encrypting at least one of the 
parts for a key facility so as t o produce a further encrypted part, combining the 
further encrypted part and a remaining encrypted part so_as_to produce a data 
block, signing the data block and sending the data block to the key facility; 
at the key facility: 
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receiving the data block from the sender facility, forwarding the data block 
to the receiver facility, and logging receipt of the data block from the sender 
facility; 

at a receiver facility: 

receiving the data block from the key facility, and requesting decryption of 

the further encrypted part by the key facility; 

at the key facility: 

logging receipt of the decryption request from the receiver facility as proof 
of delivery of the data block to the receiver facility, decrypting the further 
encrypted part eB-after_receipt of the request from the receiver facility, and 
sending the decrypted further encrypted part to the receiver facility; 
at the receiver facility: 

decrypting the encrypted part and the decrypted further encrypted part 

provided by the key facility; and 
at the sender facility: 

requesting proof of delivery information from the key facility. 
30. (currently amended) A method of transferring data, comprising: 
at a sender facility: 

encrypting data for an intended recipient, splitting the data into encrypted 
parts such that no part is decryptable on its own, encrypting at least one of the 
parts for a key facility so as to produce a further encrypted part, combining the 
further encrypted part and a remaining encrypted part soasjo produce a data 
block, signing the data block and sending the data block to a receiver facility; 
at the receiver facility: 

receiving the data block from the sender facility, and requesting decryption 
of the further encrypted part by the key facility; 
at the key facility: 

logging receipt of the further encrypted part, decrypting the further 
encrypted part ea-after receipt of the request from the receiver facility and sending 
the decrypted further encrypted part to the receiver facility; 
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at the receiver facility: 

decrypting the encrypted part and the decrypted further encrypted part 

provided by the key facility. 
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